Hacker News new | past | comments | ask | show | jobs | submit
What GrapheneOS is missing is a complete backup and restore solution so that people can preventively wipe their smartphone before crossing the border. It would be nice to have the possibility to backup/restore every app and their data from an ssh/sftp server the way google/apple users do with google cloud / icloud. I'd rather wipe my smartphone, only add a couple of direct contacts, a copy of my passport and the pdf of my plane tickets, take the plane and cross the border with a smartphone with very little but real personal data they already know and be able to provide my PIN/password to law enforcement if they ask for it, abiding with law if such a law exist (which is the case in my home country), than using a duress and risk prosecution.

Sure that doesn't protect your data from any other attack vector but it allows you to travel with less risk of getting detained by law enforcement of a country you are visiting. You get asked your password, you can give it, and they see a phone that is used like a dumbphone. If you get questioned for that a simple "my phone died yesterday, a friend just gave me his old pixel". If you need more stuff/information during your travel you would basically only need to remember the passphrase to access a password manager or a remote ssh server but you can restore only the stuff you need when travelling and and wipe again at any moment.

Having said that maybe it is better to set this up some way but not have it builtin so that law enforcement doesn't expect that any grapheneos user would have his data on an sftp server somewhere by default. Otherwise we are back to point 0 where they would ask to connect to it and restore to a phone they own. Oh and have a dummy google account you only used to purchase a couple of silly stuff on amazon, aliexpress and shein and random subscription of various "non risky subjects" on youtube. The gmail address would quickly be filled with enough spam to look genuine.

I am travelling abroad in 3 weeks for a month and I am seriously considering wiping up my grapheneOS phone before flying. I am wary that I could be targeted at a border just for having a google pixel with grapheneOS. Or maybe I should just leave my main phone at home and only travel with a new empty 150€ phone with only my main family emergency contacts. I don't remember ever being asked to show my smartphone at a border but you never know when it will happen. Thanksfully until you reboot it there is nothing that shows from the lockscreen that it is not running the regular google pixel android.

GrapheneOS includes an encrypted backup system covering far more data than Google cloud backups. It backs up data for apps opting out of cloud backups with allowBackup="false" since it operates in the device-to-device transfer mode. The backup system supports arbitrary sync services with a compatible API. Backups are per-profile so you can test it by restoring to a secondary user.

We plan to entirely overhaul the backup system but it already works fine. It could be a lot simpler and cleaner both in terms of implementation and user experience. We're in the process of overhauling the other apps first but we'll get to it.

A replacement for SeedVault is planned:

https://grapheneos.org/features#encrypted-backups

https://github.com/GrapheneOS/os-issue-tracker/issues/4687#i...

> the project has been taken over by another group of people not sharing our goals or approach

> Seedvault which was originally written for use in GrapheneOS by a GrapheneOS user is a consequence of the 2018 takeover attempt on the project, which the people currently in defacto control of Seedvault were heavily involved in.

Seedvault is currently maintained by the CalyxOS team but I've never heard about this stuff. Does anybody know what happened?

There has been a lot of conflict between Calyx and GrapheneOS a while ago.
Yeah, it's planned for years and years at this point.

Sure I know there are more urgent priorities but at the moment there is no backup for GOS phones. It only works for some people in some situations. For me it never reliably worked, ever.

Neat, I didn't realize it was still included. I thought it had been abandonned.

So basically one needs a webdav server somewhere or an usb flash drive.

The problem is that most apps opt out of backup, so it's effectively useless.
Yeah I don't even understand why this is even a thing. It should be user's choice, not app vendor/developer's choice.
loading story #49059839
Android 12 changed the meaning of allowBackup="false" to opting out of cloud backups. GrapheneOS encrypted backups use the device-to-device transfer mode which includes apps opted out of cloud backups. It's similar to the Google Play data transfer feature, not Google's backup system.
loading story #49060073
I use Seedvault to create a backup locally on my phone, and then sync it to my backup server with Syncthing
I use local seedvault backup and then sync via round sync daily trigger to my Nextcloud WebDav Server (native seedvault was not able to use this, for some reason).
It's been planned for years...
TTS has also been planned for a while and they released it recently. Donating or helping out is going to do more than complaining on HN.
loading story #49060846
loading story #49058466
I think more useful would be to be able to boot into another data partition with a different password, which, in turn, would hide the other "daily" partition. I believe LUKS is capable of that. The storage dump looks like a random set of data and only a valid password can find and decrypt a matching hidden partition.

Ideally this should also work on lock screen, e.g. if you type in a non-standard PIN, it would boot from the "dummy" partition in the background, with a slight delay perhaps.

This way you don't have backup anything (I mean you should, but for normal purposes) and have a plausible deniability whenever you get randomly inspected, not just at border crossings that you anticipate.

>I believe LUKS is capable of that

Booting into a 30 GB partition on a 128GB phone is going to be mega suspicious, even if the remaining data is random.

A partition based on a sparse disk image might avoid that.

You'd have what appears to be a 128GB image (or some large fraction of that), which in reality is largely holes (typically: repeated blocks of ASCII 00 bytes).

Of course, you'd need to avoid actually trying to fill that filesystem.

There are ways around it AFAIK.
loading story #49061292
Right, it would have to be 64/64 for everyone.
Not possible to have a robust implementation with the current tech unfortunately.

https://veracrypt.io/en/Wear-Leveling.html

Interesting, did not know that! They do say some hardware, though, is phone's solid state storage definitely affected?
loading story #49062067
That isn't truly hidden and can be detected as a low level from the SSD.
No it can't. The the thing, it's obfuscated.
Having different data partition forces you to hide stuff, which can be unlawful in some juridictions.

Not having the data in the first place in some specific contexts (like crossing borders) is easier.

A complete backup is solution that can be stored on my own encrypted servers and restored with a click of a button is really needed.

I always dread the possibility of my GrapheneOS phone being damaged or stolen and having to spend hours reinstalling and reconfiguring everything that Seedvault missed, as well as losing access to accounts that are locked by the secure element keys.

> I am wary that I could be targeted at a border just for having a google pixel with grapheneOS.

Is that likely to happen at all in a civilized (Western) country?

Remind us what happened when you do cross.
Honestly, I feel like I'd be more suspicious of someone who had little to nothing installed on their phone.
A lot of people are still using their smartphone pretty much as a dumbphone with a web browser.
Yeah but if you're a normal guy strolling through every time with a phone that has nothing- no pictures, no signed in email, no history of messages, 4 contacts. That's abnormal, no way of spinning it as "but I just don't use my phone much" will make that seem normal. The average person has their phone glued to their body 24/7 now. Implying that you don't is abnormal.
"I only ever cross borders with a blank phone because I don’t want you invading my privacy" is a perfectly valid answer. You can also add that it is your employer’s policy and/or your government official recommendation.
You can also point out that other countries want to search phones too.

"I have to do this because of country X, you know that they're like, amirite?"

> a perfectly valid answer

Makes no difference at all in the real world. You don't have to give valid answers, you need to get the guy across from you to not find you suspicious. That phrase is going to put a red flag on you, valid or not.

> you need to get the guy across from you to not find you suspicious.

What? No, who cares about that? Let him find you suspicious, what matters is that he doesn’t access your data. And it is not suspicious to cross borders (esp. US borders) with burner phones. As others have said, it is standard practice.

loading story #49059748
It's one that will get you denied entry, or detained indefinitely.
I have worked for employers that required taking a burner phone to certain countries without any accounts logged in, etc. (so mostly for calls, maps, and web browsing) and nobody has ever been detained or denied entry. Some countries know that this is just standard procedure when they are visited for business trips. Probably different for the US though.

(Not legal advise of course, just observation. Always check with the legal department of your employer, etc.)

> Probably different for the US though.

After cornering themselves into being labeled an unsafe destination (long overdue imho), the US are gonna have to learn being treated as such.

"I'm here for business and my employer requires it" is an acceptable excuse. "I don't like government surveillance" is not.
Denied entry, why not. But detained?
In the USA border they detain people they think are lying until they think they are not lying.
Lying about what? "I only bring a burner phone to border checks because I don’t want people like you to access my data“ is not a lie, and I fail to see how it could be interpreted as such.
{"deleted":true,"id":49058162,"parent":49056458,"time":1785073331,"type":"comment"}
"I got on pickpocketed on my last vacation, so now I travel with an old backup phone instead"
This may feel like a good idea as a “gotcha” justification but it just doesn’t matter. It’s still extremely abnormal and you will stick out. The only way to protect yourself is by blending in, not sticking out.
loading story #49060761
loading story #49059753
Even more of a reason for good and easy backup and restore.

Before travel back up the real contents and restore a dummy travel backup with random games, stock photos etc. Then restore back to real contents.

This is never going to happen for the same reason Apple and Google won’t let you use different backup/restore methods.
I looked at snapseed a few hours ago and backup must be done per profile.

So you can totally have different profiles with different backup servers/credentials and decide to nuke one before flying or crossing a border.

Obviously you can't expect having 2 whatsapp or signal accounts on same number but you can always have several SIMs.

The good thing is with profiles you can totally seed a profile for a few weeks before travelling.

Sure but there'd be nothing there.

If the regime is going to just start taking people then nothing will stop that, but the goal is to stop the usefulness of this sort of thing as an intimidation measure - or at least drag it to the forefront and overthrow the regime.

The easiest way to avoid suspicion is to have a phone filled with cat and family pictures, dumb apps and games.

You don't avoid scrutiny by being wierd and hiding things, but by hiding in plain sight by being ultra boring.

The easiest way to avoid suspicion is to have a phone filled with cat and family pictures, dumb apps and games.

Presumably they know quite a lot about you already outside your phone (yay, Palantir). I mean, the guy the recent post was about was an activist. An empty phone vs. a phone with just cat pictures and dumb games wouldn't really make a difference. They went on a fishing expedition, so anything that does not have contact information/messages of other activists or any information that they could use against the phone owner would be a win.

(F-you Palantir for reading this message and adding it to my online record.)

> (F-you Palantir for reading this message and adding it to my online record.)

Hello Palantir. I orchestrated 9/11. Please come and arrest me.

On the other hand, if everything about you is boring, that in itself may begin to seem suspicious. "I borrowed this old phone from my stepson because my own phone got run over by a steamroller at a vintage vehicle show" is the sort of thing an actual spy or criminal would never say.
Add some dickpicks because who doesn't have something on their phone that they don't want others to see.
Multiple decoy accounts, heh. First one: cat pics. Second one: dick pics. Third one: conversations with an imaginary mistress. Fourth one: porn that's illegal in Korea. Fifth one: ....

completely impractical obviously

[flagged]
> So you plan to (1) actively/proactively conceal your data/evidence

I am not concealing data/evidence as it doesn't exists. I don't know of any law in any country that force you to hand out the key of your home to a remote state so that they can enter your country and do a search.

> and then (3) constantly restore from cloud backups?

Why constantly? Only and only if I need to access specific data (that may be available remotely without restore anyway). Full restore only when going back in my own country.

It's been normal operating procedure for many employees that travel to the US. You think they're all criminals?
Border officials don't have the right to search all of your data.

You are also not under any obligation to have it on your phone at all times.

Just like a regular cop, all they need is probable cause.
[flagged]
> Correct! Furthermore, border officials have no requirements to allow you into their country either, unless you’re a citizen there,

I'd rather have them tell me to turn back and go home than being jailed there only because I don't want them to fap at the picture of my daughters.

Unfortunately, it'll most likely go something like this: https://www.theguardian.com/us-news/2026/jul/23/cop-city-pro...
Being prosecuted because your smartphone has been setup yesterday is not the same as being prosecuted because you gave a password that wipe your phone in front of law enforcement.

In the past I have had my smartphone die a couple of days before travelling and quickly buying a smartphone so I could have a mobile line in case of emergency while travelling. This is not a totally uncommon case to have a smartphone with very little data. A lot of people never setup any cloud backup and lose all their data every so many years.

Yeah, the lesson is: do not travel to countries that treat people such in a shitty way. This has always been true. Unfortunately, for many foreigners this also applies to the US nowadays.

I guess that you are out of luck if you are a US citizen and need to return to your own country.

Do the requirement to put your social account public when applying for a US Visa still applies? I guess the USA do not have that many non US visitors these days because I don't know a lot of women who would agree to that. Almost all my female friends have been experiencing stalking from jealous ex, former colleagues/clients/patients so putting their social media account public would be a complete no-go for them.

How is the tourism industry going?